google-drive-infoleak
google-drive-infoleak copied to clipboard
patched information leak leaking full names associated with some email addresses including but not limited to gmail
edit: this has been patched. took ~5 years
how to install and use
- use google developers console to generate api credentials after enabling drive api on a new project
- edit index.php and insert your clientid, clientsecret and redirecturi starting at line 26
- your redirecturi value must be the url that points to index.php
- navigate to index.php after hosting it on a local or remote webserver

full name information leak in google drive
in 2015 i discovered and reported this leak found in both mapsengine and drive. mapsengine was patched, but it was evidently a feature in drive. many email accounts across several providers whose names aren't visible on g+ or in account recovery procedures become retrievable. this issue was disclosed to google back in 2015.
fyi
this reveals way more full names than account recovery procedures, the "to" field in new emails, etc. and as such seclists.org commentators were and still are dead wrong ¯\(ツ)/¯

lulz full disclosure